ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

Australians hit by online bank fraud

James Pearce and Stephen Withers, ZDNet Australia ZDNet Australia

Published: 18 Mar 2003 11:46 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Commonwealth Bank of Australia has revealed that some customers have been tricked into revealing their online banking client numbers and passwords after receiving a spam mail claiming to be from the bank.

The message has the subject "Netbank Security Server Update" and asks recipients to reactivate their Netbank accounts. The HTML message grabs a genuine Commonwealth Bank graphic, but the hyperlink that purports to take the reader to the NetBank site actually points to a server identified only by an IP address.

Anyone viewing the message as plain text is unlikely to be fooled, but the default setting for many email programs is to show HTML messages fully-formatted. The IP address used by the bogus Web site is apparently allocated to a Taiwanese telco, but the site itself has now been taken offline.

"If customers have received an email requesting personal information they should delete it. It is not from the Commonwealth Bank," read an advisory issued by the bank. The bank goes on to advise anyone who responded to the instructions in the fraudulent email to change their password via the Netbank site, and check their account details.

The spam contains other clues that it is fraudulent, including awkward phrasing such as "to keep your investments in safety" and grammatical errors, for example, "Due to technical update we recommend you to reactivate your account".

"We are working closely with the relevant authorities to identify persons behind these attempts to defraud," said John Geurts, head of group security at Commonwealth Bank, in a statement.

The bank is assuring customers that the Netbank system is secure.

Customers of Melbourne IT, an Australian domain name provider, have also been targeted by spammers seeking credit card details. The spam uses a malformed URL to make it appear to be from Melbourne IT, and claiming the customers need to renew their domain or risk losing it.

The Web site users are taken to has nothing to do with Melbourne IT, and does not use a secure connection, despite an "important security notice" on the site claiming it uses 128-bit SSL. Melbourne IT has issued a statement advising people to ensure that any site in which credit card details are entered is secure, which is denoted by a padlock symbol at the bottom of the browser.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
44 out of 63 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Bank seeks senior J2EE developer FX Credit Trading Role

The team are looking to for an addition member from the financial services sector who has particular experience with the field of FX, Risk or Credit ...

Credit/Interst rate Derivatives Business Analyst Investmnet Bank

Huxley Associates is looking for a Business Analyst with Project Management experience to join a leading Investment Bank. You will be joining a ...

Credit Risk Manager required for Investment Bank, London

Do you have the ambition to work as a Credit Risk Manager? Experience working in credit analysis, specifically in energy, is a sure step to take ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme